A conversation about security

April 2013 Information Security

Craig Rosewarne
Craig Rosewarne

The person who is probably most in touch with the state of information security in South Africa is Craig Rosewarne, MD of Wolfpack Information Risk and founder and chairperson of the Information Security Group of Africa (ISGA). Rosewarne deals with both private and public organisations in his efforts to increase their level of information security awareness and preparedness.

And while he says the awareness is growing, he still comes across situations where organisations are poorly prepared to deal with the current wave of cyber crime, never mind what the future holds. The publication Wolfpack brought out past year, The South African Cyber Threat Barometer estimates that R2.65 billion was lost to cyber crime in the period from January 2011 to August 2012, with just over R660 million that was not recovered. The publication is downloadable at www.securitysa.com/*infosec5.

And that is not considering the other cyber crimes, such as cyber espionage faced on a national level, and the theft of intellectual property and business strategy that has been widely publicised of late in the USA. As the article introducing this section notes, South African companies and the government are naïve if they think the cyber villains are going to pass this country by.

One of the greatest flaws in South Africa is a lack of a response mechanism to cyber attacks. We have a few private companies that can initiate a response to a commercial attack, but no national organisation to deal with the threat and despite previous talk of developing a CERT (Computer Emergency Readiness Team) for the country, it seems this has been put on the back burner.

Rosewarne is also a concerned about the lack of security skills in South Africa, both in the private and public sectors and is looking for ways in which business can work together to overcome this problem. He has already been instrumental in promoting SANS training and certifications on the continent. He admits, however, that much more is needed.

RSA 2013 Conference

Rosewarne attended the recent RSA conference and gave Hi-Tech Security Solutions a few pointers on what was discussed. The conference was attended by over 27 000 people and featured over 250 talks, giving the attendees over 20 tracks per session to choose from.

In facing the information security threats the world is threatened by, the conference highlighted the following key themes, among others:

* Big data analytics has arrived. Arthur Coviello, RSA executive chairman, said, “Caesar recognised the omens, he just did not think they applied to him. Big technology data is here – embrace it.”

* Ensure you implement and test incident response capabilities.

* Develop deep technical information security skills.

* Obtain threat intelligence from as many sources as you can.

* Focus less on ‘tick-box’ assessments and put more effort into implementation.

* Establish multiple internal and external partnerships.

Notable notes

Among the notable presentations, Rosewarne highlighted a few that stood out, although he notes that they were all well worth listening to.

Ari Juels from RSA moderated a cryptographer’s panel with some well-known gurus in the field, including Ron Rivest, Whitfield Diffie, Adi Shamir and Dan Boneh. One of the topics discussed was security and cryptography education. Stanford offers their crypto class online via massive open online courses (MOOC). Its last intake was over 150 000 students with the largest registrations after the USA being China and India.

According to these experts, cryptography as a discipline is under strain and strangely becoming less relevant today. This is because intelligence agencies are often able to bypass encryption and APTs, sometimes buried within networks for years, simply have to wait for a key to be used in the decryption stage and they are in.

A panel discussion on the CSIS 20 Critical Security Controls discussed a new standard of due care for cyber security. “The Twenty Critical Security Controls have already begun to transform security in government agencies and other large enterprises by focusing their spending on the key controls that block known attacks and find the ones that get through.” (Source: http://www.sans.org/critical-security-controls.)

On the panel, Ed Skoudis said, “we ran an exercise of analysing all the large scale breach cases we have investigated. After mapping them to the 20 controls we are confident that had the companies implemented the controls these breaches would have been prevented.”

Of course, most companies do not have the 20 controls in place and are still suffering breaches. When looking at enterprise impact investigations, the consensus is that many companies do not conduct a thorough investigation following a breach. If systems are not reviewed in detail and the threats mitigated, they will return. Regulators have also changed their attitudes regarding investigations and insist that more detailed reviews take place.

Finally, although there was much more to see and hear at the conference, Rosewarne ends with a list of which functions should be part of a crisis management team.

* An experienced public relations firm.

* Legal experts.

* Board involvement needed to support and respond.

* Intelligence gathering analysts.

* Incident response professionals.

* Forensic investigators.

* Malware analysts.

* Network traffic monitoring staff.

* Data analysis service, and

* Breach notification management and business support teams.

These types of services are seldom offered by one company, therefore ensure you have the necessary partnerships in place before an incident happens, advises Rosewarne.



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Managed security solutions for organisations of all sizes
Information Security News & Events
Cyber attackers have become significantly more sophisticated and determined, targeting businesses of all sizes. PwC’s Global Digital Trust Insights Survey 2025 Africa and South Africa highlights the urgent need for organisations to implement robust cyber risk mitigation strategies.

Read more...
From the Editor's desk: The good, the bad, and the victims
Technews Publishing News & Events
When the Internet first arrived, everyone was expecting amazing things from it, well, everyone who knew what it was and how it worked. We had the dotcom boom and bust, and it’s fair to say that if we ...

Read more...
Data resilience at VeeamON
Technews Publishing SMART Security Solutions Infrastructure Information Security
SMART Security Solutions attended the VeeamON Tour in Johannesburg in August to learn more about data resilience and Veeam’s initiatives to enhance data protection, both on-site and in the cloud.

Read more...
Identity, Security & Access Alliance focuses on intelligence and integration
SMART Security Solutions Ideco Biometrics BoomGate Systems Bosch Building Technologies Technews Publishing Integrated Solutions Surveillance Access Control & Identity Management
The Identity, Security & Access Alliance (ISAA) hosted several launch events in Johannesburg in August, showcasing the participating companies’ technical solutions with a primary focus on the solutions made possible by integrating high-quality systems to deliver comprehensive solutions.

Read more...
Get the AI fundamentals right
Technews Publishing SMART Security Solutions Leaderware Editor's Choice Surveillance AI & Data Analytics
Much of the marketing for CCTV AI detection implies the client can just drop the AI into their existing systems and operations, and they will be detecting all criminals and be far more efficient when doing it.

Read more...
SMART Surveillance Conference in Johannesburg
Arteco Global Africa Technews Publishing SMART Security Solutions Axis Communications SA neaMetrics Editor's Choice Surveillance Security Services & Risk Management Logistics (Industry) AI & Data Analytics
SMART Security Solutions hosted its annual SMART Surveillance Conference in Johannesburg in July, welcoming several guests, sponsors, and speakers for an informative and enjoyable day examining the evolution of the surveillance market.

Read more...
Troye exposes the Entra ID backup blind spot
Information Security Infrastructure
If you trust Microsoft to protect your identity, think again. Many organisations naively believe that Microsoft’s shared responsibility model covers Microsoft Entra?ID – formerly Azure AD – but it does not.

Read more...
Secure data protection without hardware lock-in
Infrastructure Information Security News & Events
New Veeam Software Appliance empowers IT teams to achieve instant protection with Veeam’s fully preconfigured, software-only appliance, delivering enterprise-ready simplified deployment and operational efficiency, robust cyber resilience.

Read more...
Check Point launches open, vendor-neutral MDR services
Information Security News & Events Products & Solutions
New Check Point MDR 360° and MXDR 360° offerings deliver 24/7 managed continuous threat monitoring protection across endpoints, cloud and network environments with built-in identity threat detection and 160+ integrations across hybrid, multi-vendor environments.

Read more...
Credential theft surges in South Africa
NEC XON Information Security
NEC XON issues a critical cybersecurity warning about the dual threat of massive credential theft and AI-powered cyberattacks sweeping across the region, with an increasing number of incidents and evolving threat tactics.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.